<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>LAYERWEB Blog - Vulnerabilities</title>
        <link>https://blog.layerweb.com.tr/category/vulnerabilities</link>
        <description>Articles in Vulnerabilities category - Expert content on cybersecurity, reverse engineering, and software development.</description>
        <lastBuildDate>Tue, 16 Sep 2025 00:00:00 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>en</language>
        <image>
            <title>LAYERWEB Blog - Vulnerabilities</title>
            <url>https://blog.layerweb.com.tr/logo-light.svg</url>
            <link>https://blog.layerweb.com.tr/category/vulnerabilities</link>
        </image>
        <copyright>© 2025 LAYERWEB. All rights reserved.</copyright>
        <item>
            <title><![CDATA[CVE-2023-44487 - HTTP/2 Rapid Reset Denial of Service]]></title>
            <link>https://blog.layerweb.com.tr/vuln/cve2023-44487-Raid-Reset-DDoS-HTTP2vuln</link>
            <guid isPermaLink="false">https://blog.layerweb.com.tr/vuln/cve2023-44487-Raid-Reset-DDoS-HTTP2vuln</guid>
            <pubDate>Tue, 16 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[A remote unauthenticated attacker can exploit the HTTP/2 Rapid Reset vulnerability to perform a high-impact denial-of-service attack by rapidly opening and resetting streams, exhausting server resources.]]></description>
            <content:encoded><![CDATA[A remote unauthenticated attacker can exploit the HTTP/2 Rapid Reset vulnerability to perform a high-impact denial-of-service attack by rapidly opening and resetting streams, exhausting server resources.]]></content:encoded>
            <category>Vulnerabilities</category>
        </item>
        <item>
            <title><![CDATA[CVE-2025-41228 - VMware vSphere Client 8.0.3.0 XSS]]></title>
            <link>https://blog.layerweb.com.tr/vuln/cve2025-41228-vmwarevcenterXSS</link>
            <guid isPermaLink="false">https://blog.layerweb.com.tr/vuln/cve2025-41228-vmwarevcenterXSS</guid>
            <pubDate>Mon, 11 Aug 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Reflected XSS in VMware vSphere Client 8.0.3.0 via unsanitized query string on /folder endpoint.]]></description>
            <content:encoded><![CDATA[Reflected XSS in VMware vSphere Client 8.0.3.0 via unsanitized query string on /folder endpoint.]]></content:encoded>
            <category>Vulnerabilities</category>
        </item>
        <item>
            <title><![CDATA[CVE-2023-43320 Proxmox VE - TOTP Brute Force]]></title>
            <link>https://blog.layerweb.com.tr/vuln/cve2023-43320-ProxmoxTOTPBrute</link>
            <guid isPermaLink="false">https://blog.layerweb.com.tr/vuln/cve2023-43320-ProxmoxTOTPBrute</guid>
            <pubDate>Wed, 31 Jan 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[Defensive advisory and mitigation guidance for reported Proxmox VE TOTP brute-force activity. PoC code omitted for safety.]]></description>
            <content:encoded><![CDATA[Defensive advisory and mitigation guidance for reported Proxmox VE TOTP brute-force activity. PoC code omitted for safety.]]></content:encoded>
            <category>Vulnerabilities</category>
        </item>
        <item>
            <title><![CDATA[CVE-2023-6553 - WordPress Backup Migration Plugin Remote Code Execution]]></title>
            <link>https://blog.layerweb.com.tr/vuln/cve2023-6553-Wordpress-Backup-Migration-RCE</link>
            <guid isPermaLink="false">https://blog.layerweb.com.tr/vuln/cve2023-6553-Wordpress-Backup-Migration-RCE</guid>
            <pubDate>Mon, 11 Dec 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[Unauthenticated remote code execution in WordPress Backup Migration plugin (≤1.3.7) via PHP filter chain injection through Content-Dir header manipulation. Critical web application vulnerability enabling complete server compromise.]]></description>
            <content:encoded><![CDATA[Unauthenticated remote code execution in WordPress Backup Migration plugin (≤1.3.7) via PHP filter chain injection through Content-Dir header manipulation. Critical web application vulnerability enabling complete server compromise.]]></content:encoded>
            <category>Vulnerabilities</category>
        </item>
        <item>
            <title><![CDATA[CVE-2019-3924 - MikroTik RouterOS Firewall and NAT Bypass]]></title>
            <link>https://blog.layerweb.com.tr/vuln/cve2019-3924-RouterOSv6</link>
            <guid isPermaLink="false">https://blog.layerweb.com.tr/vuln/cve2019-3924-RouterOSv6</guid>
            <pubDate>Thu, 21 Feb 2019 00:00:00 GMT</pubDate>
            <description><![CDATA[Remote unauthenticated proxying of traffic through MikroTik RouterOS via agent binary probes. Demonstrates WAN-to-LAN access and firewall/NAT bypass.]]></description>
            <content:encoded><![CDATA[Remote unauthenticated proxying of traffic through MikroTik RouterOS via agent binary probes. Demonstrates WAN-to-LAN access and firewall/NAT bypass.]]></content:encoded>
            <category>Vulnerabilities</category>
        </item>
    </channel>
</rss>